Sunday, September 11, 2011

CENELEC Standard: Faults and Effects


From the Desk of
Sandeep Patalay

CENELEC Standard: Faults and Effects


Effects of single faults
It is necessary to ensure that the system/sub-system/equipment meets its THR in the event of single random fault. It is necessary to ensure that SIL 3 and SIL 4 systems remain safe in the event of any kind of single random hardware fault which is recognized as possible. Faults whose effects have been demonstrated to be negligible may be ignored. This principle, which is known as fail-safety, can be achieved in several different ways:

1) Composite fail-safety
With this technique, each safety-related function is performed by at least two items. Each of these items shall be independent from all others, to avoid common-cause failures. Non-restrictive activities are allowed to progress only if the necessary number of items agree. A hazardous fault in one item shall be detected and negated in sufficient time to avoid a co-incident fault in a second item.

2) Reactive fail-safety
This technique allows a safety-related function to be performed by a single item, provided its safe operation is assured by rapid detection and negation of any hazardous fault (for example, by encoding, by multiple computation and comparison, or by continual testing). Although only one item performs the actual safety-related function, the checking/testing/detection function shall be regarded as a second item, which shall be independent to avoid common-cause failures.

3) Inherent fail-safety
This technique allows a safety-related function to be performed by a single item, provided all the credible failure modes of the item are non-hazardous. Any failure mode which is claimed to be incredible (for example, because of inherent physical properties) shall be justified using the procedure defined in Annex C. Inherent fail-safety may also be used for certain functions within Composite and Reactive fail-safe systems, for example to ensure independence between items, or to enforce shut-down if a hazardous fault is detected.

Whichever technique or combination of techniques is used, assurance that no single random hardware component failure mode is hazardous shall be demonstrated using appropriate structured analysis methods. The component failure modes to be considered in the analysis shall be identified using the procedures defined in Annex C.

In systems containing more than one item whose simultaneous malfunction could be hazardous, independence between items is a mandatory precondition for safety concerning single faults. Appropriate rules or guidelines shall be fulfilled to ensure this independence. The measures taken shall be effective for the whole life-cycle of the system. In addition, the system/sub-system design shall be arranged to minimize potentially hazardous consequences of loss-of-independence caused by, for example, a
Systematic design fault, if it could exist.


 Detection of single faults
A first fault (single fault) which could be hazardous, either alone or if combined with a second fault, shall be detected and a safe state enforced (i.e.: negated) in a time sufficiently short to fulfill the specified quantified safety target. Demonstration of this shall be achieved by a combination of Failure Modes and Effects Analysis (FMEA) and quantified assessment of Random Failure Integrity.

In the case of Composite fail-safety, this requirement means that a first fault shall be detected, and a safe state enforced, in a time sufficiently short to ensure that the risk of a second fault occurring during the detection-plus-negation time is smaller than the specified probabilistic target. In the case of Reactive fail-safety, this requirement means that the maximum total time taken for detection-plus-negation shall not exceed the specified limit for the duration of a transient, potentially hazardous, condition.

Effects of multiple faults
A multiple fault (for example, a double or triple fault) which could be hazardous, either directly or if combined with a further fault, shall be detected and a safe state enforced (i.e.: negated) in a time sufficiently short to fulfill the specified safety target. A suitable method, for example Fault Tree Analysis (FTA), shall be used to demonstrate the effects of multiple faults. The techniques used to achieve detection-plus-negation of multiple faults within the permitted time shall be shown, including supporting calculations.

Saturday, September 3, 2011

ISSUES IN TPWS (ETCS-LEVEL 1) OPERATIONS ON SOUTHERN RAILWAY


Back Ground: TPWS (Train Protection and Warning System), term used by Indian Railways, It applies to the ETCS Level 1 concepts and the UIC/UNISIG specifications. It does not, in Indian terms, apply to the UK implementation that is based on different technology.


The TPWS project on Southern Railway installed in the Chennai Central/ Chennai Beach – Gummidipundi section of Chennai division was commissioned on 2nd May 2008 on 4 EMU rakes to begin with. The works on the balance 37 rakes were progressively completed in the next few months. Presently all the 41 rakes proposed to be provided with TPWS on-board equipments are functional. The TPWS track side equipments in the section were fully provided, commissioned and made functional right from the date of commissioning.

Problems: This TPWS project based on the European Train Control System (ETCS) Level-I system faced many hurdles during the initial installation, proto-type testing, obtaining the required clearances from RDSO and CRS. The major problems noticed during initial revenue service included
1. On-Board system not booting.
2. On-Board system going into System failure (SF) during booting.
3. SDMI ( Simplified Driver Machine Interface) going blank.
4. Speed display bouncing on the SDMI leading to braking.
5. Brake application in the rear non-driving motor coach on run.

Corrective Actions Taken by Railways: 
1. Intermittent BTM failure: - Analysis revealed that there was antenna impedance mismatch. The standing wave ratio (SWR) was found more than the tolerance limit of 1.2 to 1.4. Interference from EMI was also suspected. There was problem in communication between the onboard computer (OBC) and BTM. The corrective actions for these problems included modifying the existing antenna protection cover and providing copper braided shields for the Tx-Rx cable between antenna and BTM and for the COTDL and PROFIBUS cable between OBC and BTM. The BTM configuration files were also modified
based on some internal parameters.

2. Error in Train Interface Unit: - Analysis revealed that there was problem in communication between some modules of the OBC and now screened twisted pair cables have been introduced to protect the signals from external noise and EMI.


3. Error in Speed Sensor: - To improve the performance of the Odometric system, the signal cables between OBC and speed sensors have been provided with copper braided shield firmly connected to the coach body. To suppress the noise in the 110V DC voltage derived from the motor coach battery, a filter has been provided at the input point of the OBC. The traction control relay has been shifted outside the OBC cubicle to reduce EMI. To improve earthing of the motor coach body, a 50 sq mm copper cable is to be connected between the EMU body and its bogie.

4. Back EMF from the EB & EP relay coils: - To cover come this problem, the relay coils and EB valve solenoid coils to be terminated with 180/200V MOVRs and the body of EB & SB relays to be firmly connected to the coach body.

5. EB application in rear coach:- To overcome the problem of application of EB in the rear coach while running, the brake interface circuit has been modified to bypass the EB when the TPWS system in the sleeping mode (SM) i.e., when the cab is not the driving one.

6. SDMI Blanking:- To overcome the problem of SDMI blanking, its software has been upgraded. Apart from this, the OBC-SDMI communication cable connector cover which was earlier plastic has been changed to metallic. The OBC-SDMI communication cable and the SDMI power supply cable have been shielded with copper braids firmly connected to the coach body. A filter has been provided at the 110 VDC input point of the SDMI to suppress the ripples in the power supply.

(Source: IRSTE)

Thursday, September 1, 2011

India advances high-speed studies


Indian Railway Construction Company (Ircon) has appointed Mott MacDonald to carry out a pre-feasibility study on a 993km high-speed line from Delhi to Agra, Lucknow, Varanasi, and Patna.
Mott MacDonald will identify key issues for the development of the project including environmental impacts and assessment of viable technologies. It will also analyse operational and business requirements, including ridership, capital cost, cost-benefit analysis, and development of a planning and implementation schedule.
The project is part of the Indian Government's Vision 2020 long-term national development plan, which envisages four high-speed projects in separate areas of the country, all implemented as public-private partnerships.
A pre-feasibility study on the Ahmedabad - Mumbai - Pune route was recently presented to the Railways Board, and puts the cost of this 634km line at Rs 560bn ($US 12.7bn). Western Railway says trains will operate at up to 350km/h to provide an Ahmedabad - Mumbai journey time of around two hours, compared with 7h 5min by Shatabdi train at present.
Originally these proposals covered only the 555km Mumbai - Ahmedabad section, although the Maharashtra government has lobbied for Pune to be included.

Saturday, August 6, 2011

FailSafe and Fault Tolerant Railway Systems

(Click here to view this article in Fullscreen)

Vision and Potential for Future Signalling Stratergies

(Click here to view this article in Fullscreen)

The Current Status of Signal Control Systems and Research and Development

(Click here to view this article in Fullscreen)

Tool Support for Checking Railway Interlocking Designs

(Click here to view this article in Fullscreen)

Software Safety:Where is the Evidence?

(Click here to view this article in Fullscreen)